THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-41862 (HIGH 8.8) — Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enforcing a class allowlist (CWE-502, deserialisation of untrusted data), which can lead to remote code execution inside the application

[NVD] CVE-2026-41862 (HIGH 8.8) — Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enforcing a class allowlist (CWE-502, deserialisation of untrusted data), which can lead to remote code execution inside the application

lownvdPublished 2026-06-23

CVE-2026-41862 CVSS: 8.8 HIGH Published: 2026-06-23T21:16:57.820

Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enforcing a class allowlist (CWE-502, deserialisation of untrusted data), which can lead to remote code execution inside the application JVM.

Affected versions: Spring Statemachine 4.0.0 thr

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-41862